Permissions are not enforced

Hi,

Before we close this, let me offer just a little more information:

Nope. Instead, it’s about what permissions you make available to your users. (More below).

We don’t offer direct support, but this guy got it working

Assuming you’ve locked your instance down to require login, then nothing’s truly “public”. Beyond that, it’s about how you configure your permission template. If you don’t want new projects to be visible to all logged in users, first remove any permissions granted to “Anyone” in your permissions template, then also remove “Browse” (and probably “See Source Code”) from the sonar-users group.

 
Ann